CVE-2026-23907 is a path traversal vulnerability in the ExtractEmbeddedFiles example shipped with Apache PDFBox Examples (org.apache.pdfbox:pdfbox-examples). The vulnerable code affects versions 2.0.24 through 2.0.36 and 3.0.0 through 3.0.7. The issue arises because the filename returned by PDComplexFileSpecification.getFilename() is appended directly to the extraction path without sufficient validation or restriction, allowing directory traversal sequences in embedded-file names from a crafted PDF to influence the final output path. Apache states the example was updated to canonicalize both the initial extraction directory and the candidate extraction path and to verify that the extraction path remains within the intended base path; documentation was also adjusted. The issue is specifically relevant to users who copied the example code into production applications.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository is a proof-of-concept for a path traversal / arbitrary file write issue in Apache PDFBox embedded-file extraction logic (pattern taken from the ExtractEmbeddedFiles example). It contains: (1) create_malicious_pdf.py (Python/pypdf) which generates malicious_path_traversal.pdf embedding a file whose filename is set to ../../../../../tmp/path_traversal_poc (both /F and /UF), with attacker-controlled content; (2) TestPathTraversal.java (Java/PDFBox) which loads a supplied PDF, walks the EmbeddedFiles name tree, and writes each embedded file to disk using vulnerable concatenation (filePath + filename) without sanitization, creating parent directories and writing bytes via FileOutputStream; it also prints canonical paths to highlight traversal; (3) test_path_traversal.sh which automates cleanup, PDF generation, compilation against a local pdfbox-app.jar, execution, and verification that /tmp/path_traversal_poc was created. No network activity is present; the primary observable targets are filesystem paths (notably /tmp/path_traversal_poc). The exploit capability is arbitrary file write outside the intended extraction directory when a victim application extracts embedded files from an attacker-supplied PDF using the vulnerable pattern.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.